Scope all five CCPA triggers, run the assessments, and keep every response, finding, and sign-off filing-ready for April 2028. Your rules, your team in control.









A documented evaluation, required before processing that presents significant risk to consumers' privacy, weighing the purpose and benefits of the processing against its risks and safeguards. The requirement comes from the CPPA regulations finalized in September 2025.
Obligations began January 1, 2026. Assessments for processing already underway must be complete by December 31, 2027, and the first attestation and summary must be submitted to the CPPA by April 1, 2028.
Yes. The B2B and employee exemptions expired in 2023. If your company meets the thresholds, individual account holders, business contacts, and California employees are covered consumers. Employee data alone puts many companies in scope.
Technology that processes personal information and replaces or substantially replaces human decisionmaking on a significant decision. Ordinary commercial features can qualify: dynamic pricing, automated credit terms, fraud scoring. Requirements take effect January 1, 2027. Complyance captures how each system makes decisions, so your counsel makes the qualification call on a documented record.
Businesses whose processing presents significant risk to security must complete annual audits, with certifications due to the CPPA on a staggered schedule starting April 1, 2028 for businesses over $100M in annual revenue.